漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place crafted content in a profile could cause unintended code to execute with the application's privileges when a victim views that profile. A server-side mitigation has been deployed that also protects existing Android clients that have not been updated to version 26.7.2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
N/A
Vulnerability Title
LY Corporation LINE client for Android 代码注入漏洞
Vulnerability Description
LY Corporation LINE client for Android是LY Corporation公司的一款安卓平台即时通讯客户端。 LY Corporation LINE client for Android 26.7.2之前版本存在代码注入漏洞,该漏洞源于个人资料渲染组件未能充分验证或隔离嵌入在个人资料模板中的外部提供的脚本内容,可能导致攻击者以应用程序权限执行意外代码。
CVSS Information
N/A
Vulnerability Type
N/A